home > posts
  • December 4, 2024
    HD Moore
    @hdm

    My session on "The Unreasonable Effectiveness of Inside Out Attack Surface Management" is starting in a few minutes and will showcase some simple (but useful!) tricks for finding sneaky network exposures: https://dr-resources.darkreading.com/free/w_runz04/

    Hope to see you soon!

    ↪ reply
  • December 3, 2024
    HD Moore
    @hdm

    Hi folks! I'm thrilled to present runZero's latest applied research: "Inside Out Attack Surface Management". With IOASM you can immediately identify exposures that other approaches miss, with zero false positives, and no additional investment. Join me for a live demo on Wednesday, December 4th at 1PM EST: https://dr-resources.darkreading.com/free/w_runz04/

    ↪ reply
  • December 2, 2024
    HD Moore
    @hdm

    #golang 

    At least they are using #golang https://www.ac3.com.au/resources/discovery-of-CVE-2024-2550/

    ↪ reply
  • December 1, 2024
    HD Moore
    @hdm

    It was much easier to replace my ESXi lab servers with Proxmox than to download a security update[1. see alt text] for ESXi post-Broadcom. Now ESXi runs as a scan target inside of Proxmox and all is well.

    ↪ reply
  • December 1, 2024
    HD Moore
    @hdm

    Ben Reardon shared an awesome (and funny) post on the Corelight blog about his experience at the Black Hat USA NOC (2024) and his process for detecting runZero's SSHamble.com research scans in real-time. Rob and I had a great time chatting with Ben and getting to the see Black Hat NOC up close: https://corelight.com/blog/black-hat-usa-2024-noc-learnings

    ↪ reply
  • November 28, 2024
    HD Moore
    @hdm

    Happy Thanksgiving to my fellow US-ians. This is an annual reminder that Base64 can decode different input to the same output. "Secrets" decodes from U2VjcmV0cw==, U2VjcmV0cw=, U2VjcmV0cw, U2VjcmV0cx, U2VjcmV0c9, and sometimes U2V|jcm|V0c|9.

    Base64 makes a bad hash or lookup key!

    ↪ reply
  • November 21, 2024
    HD Moore
    @hdm

    #infosec  #hackers  #atx 

    Hello Austin hackers! Tonight is the November AHA meetup (shifted back a week to avoid holiday overlap). Same place and time as usual (Mister Tramps, talks start at 7:00pm). Haven't been to an AHA before? Check out the meeting info (and bring a ~5-10m lightning talk): https://takeonme.org/ #infosec #hackers #atx

    ↪ reply
  • November 16, 2024
    HD Moore
    @hdm

    Good morning RowdyCon! I'm excited to share some serious NumberWang[1] with the San Antonio hacker crowd. RowdyCon is open to ALL students in a degree programs based in San Antonio (online or in-person). Registration is available at https://www.rowdycon.org/

    1. https://www.youtube.com/watch?v=0obMRztklqU

    ↪ reply
  • November 14, 2024
    HD Moore
    @hdm

    #golang  #atx 

    Austin Go(phers): it's that time again! Tonight is the November ATX Golang Meetup. Charles Southerland and I will both be speaking. Swing by for pizza, beer, and general nerdiness around Go. Tonight's meetup is at 7:00pm at the Capital Factory on floor 16 (in the "ACL" room):

    https://www.meetup.com/atxgolang/events/301842149/

    #golang #atx

    ↪ reply
  • November 12, 2024
    HD Moore
    @hdm

    Secure your IoT devices by (accidentally) encasing them in concrete. Fortunately this is a POE doorbell and doesn't require battery changes. It does prevent someone from easily getting to the reset button under the bottom lip; does this count as embedded security?

    ↪ reply
  • << View newer posts View older posts >>

Copyright 1998-2025 HD Moore